Developer documentation
MCP tools, resources, and prompts
Tool discovery is filtered for convenience, while every invocation independently checks scope, environment, organization membership, and sensitive role permissions.
Tools
Each tool uses the same canonical domain input and domain result as its REST action. Mutations require idempotency_key. Destructive actions require confirm: true and advertise destructiveHint.
Resources
Read frequently inspected benefits, policies, evaluations, and imports through veltor://test/... or veltor://live/... URIs. Resources remain subject to the same access checks.
Prompts
Optional prompts guide policy review, denial investigation, and safe simulation. Prompts grant no authority and cannot bypass confirmation or scopes.